SecurityCore release 0.1.0

Relayer security

The hosted Devnet relayer's restricted transaction policy, key boundary, process-local controls and audit status.

The hosted relayer is a centralized Devnet fee payer. Its signing key can authorize only a prepared transaction that passes strict v0, signer, instruction, account, LUT, root, nullifier, compute, fee, rent and size policy.

What the service does not receive

The API accepts only base64 serialized public transaction bytes. It does not accept a wallet seed, spend secret, view key, witness, NoteStore key, proving key or private balance. A proof and public inputs are part of the public transaction.

The relayer is visible as fee payer and pays network fees and allowed rent. It is not the private trader and receives no note authorization witness through the documented relay flow.

Residual operational risks

  • The service is centrally hosted and not independently audited.
  • Rate limiting, idempotency, replay coordination and concurrency state are process-local in v1, not durable or globally shared.
  • The reserve check is not an atomic cross-instance budget reservation.
  • The relayer sees request timing, transport origin and public transaction details; it is not network anonymity.
  • RPC, hosted deployment and relayer key operations are operational trust boundaries.

On-chain nullifier state remains the global spend-replay authority. The service's memory state is defense in depth and availability/economic protection, not the protocol authorization source.

See Relayer policy, Status & replay and Known limitations.

PreviousTrusted setupNext Note security & backups
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.